skills/awslabs/aidlc-workflows/aidlc/Gen Agent Trust Hub

aidlc

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes local orchestration tools and an engine binary (referenced via the {{INVOKE}} placeholder) to manage development states, logs, and workflow transitions. It incorporates explicit logic for shell-safe argument escaping (supporting both POSIX and PowerShell quoting) when passing user-provided text to these commands.
  • [INDIRECT_PROMPT_INJECTION]: The orchestrator has a inherent attack surface as it processes data from external tool directives, project files, and user input.
  • Ingestion points: Ingests data from orchestration directives (e.g., narration, question, rules_content), user-supplied arguments, and project-local files like stage_file and consumes manifests.
  • Boundary markers: The instructions mandate verbatim reproduction of tool-generated narration and use structured question rendering (via AskUserQuestion) to maintain clear separation between system instructions and external content.
  • Capability inventory: The skill is capable of executing shell commands, reading project files, and dispatching tasks to sub-agents.
  • Sanitization: It implements shell-safe escaping for user-supplied strings to mitigate command injection risks at the interface with local tools.
  • [DYNAMIC_EXECUTION]: The skill dynamically dispatches work to specialized agent personas (e.g., aidlc-product-agent, aidlc-architect-agent) using a Task() mechanism based on the current workflow stage and instructions provided by the local orchestration engine. This behavior is standard for a multi-agent workflow system and is governed by a central conductor persona.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 07:25 PM
Security Audit — agent-trust-hub — aidlc